// const token = document.getElementsByName('csrf')[0].value


function sendFormData(formdata, url) {
	const headers = new Headers()
	headers.append("Content-Type", "aaplication/x-www-form-urlencoded")
	const request = new Request(url, {
		method: "POST",
		body: formdata,
	});
	fetch(request)
		.then((response) => {
			if (response.status === 200) {
				return response.json();
			} else {
				throw new Error("Что-то пошло не так на API сервере.");
			}
		})
		.then((response) => {
			console.debug(response);
			// ...
		})
		.catch((error) => {
			console.error(error);
		});
}

function createFormData(arr) {
	let formData = new FormData();
	for (let { key, value } in arr) {
		formData.append(key, value);
	}
	return formData
}


let f = createFormData([
	{ csrf: "2EdRR2skYcTW2fN3arlfvNYkk3fAfQcI" },
	{ postId: "7" },
	{ comment: "12345 5455454354 34543543 43534534" },
	{ name: "=================" },
	{ email: "adw@wedw.33" },
	{ website: "" },
])


sendFormData(f, 'https://0a5000420300e689807bee6100b5009d.web-security-academy.net/post/comment')